CVE-2024-2369

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Configurations

Configuration 1 (hide)

cpe:2.3:a:godaddy:coblocks:*:*:*:*:*:wordpress:*:*

History

13 May 2025, 01:07

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/252dfc35-4c8c-4304-aa09-73dfe986b10d/ - () https://wpscan.com/vulnerability/252dfc35-4c8c-4304-aa09-73dfe986b10d/ - Exploit, Third Party Advisory
First Time Godaddy coblocks
Godaddy
CPE cpe:2.3:a:godaddy:coblocks:*:*:*:*:*:wordpress:*:*
CWE CWE-79

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/252dfc35-4c8c-4304-aa09-73dfe986b10d/ - () https://wpscan.com/vulnerability/252dfc35-4c8c-4304-aa09-73dfe986b10d/ -

31 Oct 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

08 Apr 2024, 18:15

Type Values Removed Values Added
Summary (en) The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks (en) The Page Builder Gutenberg Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

02 Apr 2024, 12:50

Type Values Removed Values Added
Summary
  • (es) El complemento Page Builder Gutenberg Blocks de WordPress anterior a 3.1.7 no valida ni escapa algunas de sus opciones de bloqueo antes de devolverlas a una página/publicación donde está incrustado el bloque, lo que podría permitir a los usuarios con el rol de colaborador y superior realizar ataques de Cross-Site Scripting

02 Apr 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 05:15

Updated : 2025-05-13 01:07


NVD link : CVE-2024-2369

Mitre link : CVE-2024-2369

CVE.ORG link : CVE-2024-2369


JSON object : View

Products Affected

godaddy

  • coblocks
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')